


Perceptive Security
SOC/SIEM Consultancy

Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system comm…
Published:
23 April 2026 at 00:00:00
Alert date:
23 April 2026 at 18:00:49
Source:
cisa.gov
Web Technologies
CVE-2026-39987 is a critical pre-authorization remote code execution vulnerability in Marimo that allows unauthenticated attackers to gain shell access and execute arbitrary system commands. This vulnerability poses a high security risk as it requires no authentication and can lead to complete system compromise. The vulnerability has been documented by CISA and tracked on GitHub security advisories. Given the nature of remote code execution without authentication requirements, this represents a severe security flaw that could be easily exploited by malicious actors. Organizations using Marimo should prioritize patching this vulnerability immediately.
Technical details
Mitigation steps:
Affected products:
Marimo
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-39987
https://github.com/marimo-team/marimo/security/advisories/GHSA-2679-6mx9-h9xc
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
